You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

SpringBoot出现Pre-authenticated entry point called. Rejecting access错误求助

问题排查:Spring Boot /api/public/register接口返回403 Forbidden

错误日志

o.s.web.servlet.DispatcherServlet        : Completed initialization in 4 ms
o.s.security.web.FilterChainProxy        : Securing POST /api/public/register
o.s.s.w.a.AnonymousAuthenticationFilter  : Set SecurityContextHolder to anonymous SecurityContext
o.s.s.w.s.HttpSessionRequestCache        : Saved request http://localhost:8080/api/public/register?continue to session
o.s.s.w.a.Http403ForbiddenEntryPoint     : Pre-authenticated entry point called. Rejecting access
o.s.security.web.FilterChainProxy        : Securing POST /error
o.s.security.web.FilterChainProxy        : Secured POST /error
o.s.web.servlet.DispatcherServlet        : "ERROR" dispatch for POST "/error", parameters={}
s.w.s.m.m.a.RequestMappingHandlerMapping : Mapped to org.springframework.boot.autoconfigure.web.servlet.error.BasicErrorController#error(HttpServletRequest)
o.j.s.OpenEntityManagerInViewInterceptor : Opening JPA EntityManager in OpenEntityManagerInViewInterceptor
o.s.w.s.m.m.a.HttpEntityMethodProcessor  : Using 'application/json', given [*/*] and supported [application/json, application/*+json]
o.s.w.s.m.m.a.HttpEntityMethodProcessor  : Writing [{timestamp=Mon Jan 20 05:51:15 EST 2025, status=403, error=Forbidden, path=/api/public/register}]
o.j.s.OpenEntityManagerInViewInterceptor : Closing JPA EntityManager in OpenEntityManagerInViewInterceptor
o.s.web.servlet.DispatcherServlet        : Exiting from "ERROR" dispatch, status 403

核心问题分析

从日志能看到:

  • 接口已被识别为需要安全校验,且已设置匿名上下文,但仍触发了Pre-authenticated entry point的拒绝逻辑
  • 请求被缓存到Session(带continue参数),说明可能存在请求缓存的干扰

排查与解决步骤

1. 确认Spring Security配置是否放行匿名访问

最常见的原因是公共注册接口未被加入安全白名单。检查你的Security配置类,确保/api/public/register路径被允许匿名访问:

@Configuration
@EnableWebSecurity
public class SecurityConfig {

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
            .authorizeHttpRequests(auth -> auth
                .requestMatchers("/api/public/register").permitAll() // 必须添加这行
                .anyRequest().authenticated()
            )
            // 其他配置...
        ;
        return http.build();
    }
}

注意:如果使用了antMatchers(旧版Spring Security),替换为requestMatchers即可。

2. 排查预认证相关配置

如果项目中使用了预认证过滤器(比如PreAuthenticatedAuthenticationFilter),需要确保该过滤器仅作用于需要预认证的路径,不要覆盖公共接口:

  • 检查是否给预认证过滤器设置了正确的路径匹配规则,避免拦截/api/public/register
  • 若不需要预认证功能,直接移除相关配置类或过滤器Bean

3. 调整HttpSessionRequestCache配置

日志中显示请求被缓存,可能导致后续重定向时触发权限校验。可以配置忽略公共路径的请求缓存:

@Bean
public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
    http
        .requestCache(cache -> cache
            .requestCache(new HttpSessionRequestCache() {
                @Override
                public void saveRequest(HttpServletRequest request, HttpServletResponse response) {
                    // 忽略公共路径的请求缓存
                    if (!new AntPathMatcher().match("/api/public/**", request.getRequestURI())) {
                        super.saveRequest(request, response);
                    }
                }
            })
        )
        // 其他配置...
    ;
    return http.build();
}

4. 验证请求参数与头信息

  • 检查请求是否携带了多余的认证头(比如Authorization),导致预认证过滤器误触发
  • 确认continue参数是否合法,是否被安全框架识别为特殊参数引发拦截

内容的提问来源于stack exchange,提问作者Prasanth Kunchanapalli

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.14 23:12:33